US2010180120A1PendingUtilityA1

Information protection device

Assignee: HUMAN INTERFACE SECURITY LTDPriority: Sep 6, 2007Filed: Sep 3, 2008Published: Jul 15, 2010
Est. expirySep 6, 2027(~1.1 yrs left)· nominal 20-yr term from priority
H04L 9/3231H04L 2209/805H04L 63/0853H04L 9/3263H04L 63/0428G06F 21/34G06F 21/83H04L 9/3234G06F 21/85
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for communication includes coupling an information protection device ( 34 ) to communicate via a local interface ( 36 ) with a local computer ( 28 ) operated by a user ( 22 ), the information protection device having an input transducer ( 58 ) associated therewith. A communication session is initiated between the local computer and a remote computer ( 24 ) over a network ( 26 ). The information protection device receives an access code input by the user via the input transducer and encrypts the access code using an encryption key held by the information protection device. The encrypted access code is conveyed from the information protection device over the local interface to the local computer and from the local computer to the remote computer over the network in order to authenticate the user at the remote.

Claims

exact text as granted — not AI-modified
1 . A method for communication, comprising:
 coupling an information protection device to communicate via a local interface with a local computer operated by a user, the information protection device having an input transducer associated therewith;   initiating a communication session between the local computer and a remote computer over a network;   receiving in the information protection device an access code input by the user via the input transducer;   encrypting the access code in the information protection device using an encryption key held by the information protection device;   conveying the encrypted access code from the information protection device over the local interface to the local computer and from the local computer to the remote computer over the network; and   authenticating the user at the remote computer by decrypting the encrypted access code.   
   
   
       2 . The method according to  claim 1 , and comprising conveying, from the information protection device over the local interface to the local computer and from the local computer to the remote computer over the network, an indication of an authentication token stored by the information protection device, wherein authenticating the user comprises verifying an identity of the user responsively to the indication. 
   
   
       3 . The method according to  claim 1 , and comprising receiving in the information protection device a biometric input by the user via a biometric sensor, and conveying an indication of the biometric input from the information protection device over the local interface to the local computer and from the local computer to the remote computer over the network, wherein authenticating the user comprises verifying an identity of the user responsively to the indication. 
   
   
       4 . The method according to  claim 1 , wherein the input transducer is selected from a group of input transducers consisting of a keypad and a keyboard. 
   
   
       5 . The method according to  claim 4 , wherein the input transducer is configured to convey unencrypted input to the local computer responsively to keystrokes by the user. 
   
   
       6 . The method according to  claim 1 , wherein the information protection device comprises a housing that contains the input transducer. 
   
   
       7 . The method according to  claim 1 , wherein coupling the information protection device comprises plugging the input transducer into a connector of the information protection device. 
   
   
       8 . The method according to  claim 1 , wherein the information protection device comprises an output transducer, for prompting the user to input the access code. 
   
   
       9 . The method according to  claim 9 , and comprising conveying a certificate from the remote computer over the network to the local computer and verifying that the certificate is valid, wherein prompting the user comprises outputting via the output transducer an indication that the certificate is valid. 
   
   
       10 . The method according to  claim 1 , and comprising, after authenticating the user, receiving information from the user via a user interface of the local computer for transmission from the local computer to the remote computer in the communication session. 
   
   
       11 . The method according to  claim 1 , and comprising, after authenticating the user, receiving in the information protection device further information that is input by the user via the input transducer, and transmitting the further information in an encrypted form from the information protection device to the remote computer via a tunneled logical path through the local computer. 
   
   
       12 . The method according to  claim 1 , wherein coupling the information protection device comprises plugging the information protection device into a receptacle in the local computer. 
   
   
       13 . The method according to  claim 1 , wherein coupling the information protection device comprises establishing a short-range wireless link between the information protection device and the local computer. 
   
   
       14 . The method according to  claim 1 , wherein encrypting the access code comprises conveying the encryption key from the remote computer over the network to the local computer and from the local computer over the local interface to the information protection device. 
   
   
       15 . A method for communication, comprising:
 coupling an information protection device to communicate via a local interface with a local computer operated by a user, the information protection device having an input transducer associated therewith;   establishing a physical communication link over a network between the local computer and a remote computer;   setting up a secure tunnel between the remote computer and the information protection device via the physical communication link and through the local computer, such that information transmitted through the secure tunnel is encrypted and can be decrypted only using a key that is unavailable to the local computer;   receiving data input by the user to the information protection device via the input transducer; and   encrypting and transmitting the data from the information protection device to the remote computer via the secure tunnel.   
   
   
       16 . The method according to  claim 15 , wherein coupling the information protection device comprises plugging the information protection device into a receptacle in the local computer. 
   
   
       17 . The method according to  claim 15 , wherein coupling the information protection device comprises establishing a short-range wireless link between the information protection device and the local computer. 
   
   
       18 . The method according to  claim 15 , wherein the information protection device comprises a housing that contains the input transducer. 
   
   
       19 . The method according to  claim 15 , wherein coupling the information protection device comprises plugging the input transducer into a connector of the information protection device. 
   
   
       20 . The method according to  claim 15 , wherein the data input by the user via the input transducer comprise first data, and wherein the method comprises receiving second data input by the user via a user interface of the local computer, and transmitting the second data together with the first data to the remote computer via the physical communication link in a single communication session. 
   
   
       21 . The method according to  claim 20 , wherein the input transducer comprises a keypad, and wherein the user interface comprises a keyboard. 
   
   
       22 . The method according to  claim 20 , wherein the secure tunnel comprises a first secure socket connection, and wherein transmitting the second data comprises setting up a second secure socket connection between the information protection device and the local computer, and conveying the second data from the local computer through the second secure socket connection to the information protection device and from the information protection device through the first secure socket connection to the remote computer. 
   
   
       23 . The method according to  claim 15 , wherein receiving the data comprises presenting a page provided by the remote computer on a display of the local computer, the page comprising a field to be filled in with the data input by the user. 
   
   
       24 . The method according to  claim 23 , wherein the secure tunnel comprises a first secure socket connection, and wherein presenting the page comprises setting up a second secure socket connection between the information protection device and the local computer, and conveying the page from the remote computer through the first secure socket connection to the information protection device and from the information protection device through the second secure socket connection to the local computer. 
   
   
       25 . The method according to  claim 24 , wherein presenting the page comprises generating an indication on the display that the field is to be filled in by the user by means of the input transducer of the information protection device. 
   
   
       26 . The method according to  claim 15 , wherein the information protection device comprises an output transducer, for prompting the user to input the data. 
   
   
       27 . The method according to  claim 26 , and comprising conveying a certificate from the remote computer over the network to the local computer and verifying that the certificate is valid, wherein prompting the user comprises outputting via the output transducer an indication that the certificate is valid. 
   
   
       28 . A system for authenticating a user of a local computer, the system comprising:
 a remote computer, which is configured to communicate over a network with the local computer;   an input transducer, which is coupled to receive an access code that is input by the user; and   an information protection device, which comprises:
 a communication interface for communicating with a local interface of the local computer; and 
 an encryption processor, which is configured to encrypt the access code using an encryption key held by the information protection device and to convey the encrypted access code via the local interface to the local computer for transmission by the local computer to the remote computer over the network, 
   wherein the remote computer authenticates the user by decrypting the encrypted access code.   
   
   
       29 . The system according to  claim 28 , wherein the information protection device comprises a memory that stores an authentication token, and is configured to convey an indication of the token through the local interface via the local computer to the remote computer over the network, and wherein the remote computer is configured to verify an identity of the user responsively to the indication. 
   
   
       30 . The system according to  claim 28 , wherein the information protection device comprises a biometric sensor, which is coupled to receive a biometric input by the user, and wherein the information protection device is configured to convey an indication of the biometric input through the local interface via the local computer to the remote computer over the network, and wherein the remote computer is configured to verify an identity of the user responsively to the indication. 
   
   
       31 . The system according to  claim 28 , wherein the input transducer is selected from a group of input transducers consisting of a keypad and a keyboard. 
   
   
       32 . The system according to  claim 31 , wherein the input transducer is configured to convey unencrypted input to the local computer responsively to keystrokes by the user. 
   
   
       33 . The system according to  claim 32 , wherein the information protection device comprises a switch that is operable to determine whether to convey data to the local computer responsively to the keystrokes in encrypted or unencrypted form. 
   
   
       34 . The system according to  claim 32 , wherein the encryption processor is configured to switch automatically between conveying data in an encrypted form and in an unencrypted form in response to a signal from the local computer. 
   
   
       35 . The system according to  claim 28 , wherein the information protection device comprises a housing that contains the input transducer. 
   
   
       36 . The system according to  claim 35 , wherein the input transducer comprises an output connector, and the information protection device comprises an input connector for receiving the output connector. 
   
   
       37 . The system according to  claim 28 , wherein the information protection device comprises an output transducer, which is configured to prompt the user to input the access code. 
   
   
       38 . The system according to  claim 37 , wherein the remote computer is configured to convey a certificate over the network to the local computer, and wherein the information protection device is configured to verify that the certificate is valid and to prompt the user to input the access code in response to an indication that the certificate is valid. 
   
   
       39 . The system according to  claim 28 , wherein the remote computer is configured to authenticate the user upon initiation of a communication session between the local computer and the remote computer, and to receive information that is input by the user via a user interface of the local computer in the communication session after authenticating the user. 
   
   
       40 . The system according to  claim 28 , wherein the information protection device is configured to receive further information that is input by the user via the input transducer after the user has been authenticated, and to transmit the further information in an encrypted form to the remote computer via a tunneled logical path through the local computer. 
   
   
       41 . The system according to  claim 28 , wherein the communication interface comprises a plug, which is configured to be received by a receptacle in the local computer. 
   
   
       42 . The system according to  claim 28 , wherein the communication interface comprises a wireless interface, which is configured to establish a short-range wireless link with the local computer. 
   
   
       43 . The system according to  claim 28 , wherein the remote computer is configured to transmit the encryption key over the network to the local computer, and wherein the information protection device is coupled to receive the transmitted encryption key transmitted from the local computer via the communication interface. 
   
   
       44 . A system for communication by a user of a
 local computer, the system comprising:   a remote computer, which is configured to establish a physical communication link with the local computer over a network;   an input transducer, which is coupled to receive data that are input by the user; and   an information protection device, which comprises:
 a communication interface for communicating with a local interface of the local computer; and 
 a processor, which is configured to set up a secure tunnel to the remote computer over the physical communication link via the local computer, and to encrypt the received data for transmission via the secure tunnel to the remote computer such that the encrypted data transmitted through the secure tunnel can be decrypted only using a key held by the remote computer that is unavailable to the local computer. 
   
   
   
       45 . The system according to  claim 44 , wherein the communication interface comprises a plug, which is configured to be received by a receptacle in the local computer. 
   
   
       46 . The system according to  claim 44 , wherein the communication interface comprises a wireless interface, which is configured to establish a short-range wireless link with the local computer. 
   
   
       47 . The system according to  claim 44 , wherein the information protection device comprises a housing that contains the input transducer. 
   
   
       48 . The system according to  claim 44 , wherein the input transducer comprises an output connector, and the information protection device comprises an input connector for receiving the output connector. 
   
   
       49 . The system according to  claim 44 , wherein the data input by the user via the input transducer comprise first data, and wherein the information protection device is configured to receive second data input by the user via a user interface of the local computer, and to transmit the second data together with the first data to the remote computer via the physical communication link in a single communication session. 
   
   
       50 . The system according to  claim 49 , wherein the input transducer comprises a keypad, and wherein the user interface comprises a keyboard. 
   
   
       51 . The system according to  claim 49 , wherein the secure tunnel comprises a first secure socket connection, and wherein the processor is configured to set up a second secure socket connection between the information protection device and the local computer, and to receive the second data from the local computer through the second secure socket connection and transmit the second data through the first secure socket connection to the remote computer. 
   
   
       52 . The system according to  claim 44 , wherein the data comprise a page provided by the remote computer for presentation on a display of the local computer, the page comprising a field to be filled in with the data input by the user. 
   
   
       53 . The system according to  claim 52 , wherein the secure tunnel comprises a first secure socket connection, and wherein the processor is configured to set up a second secure socket connection between the information protection device and the local computer, and to receive the page from the remote computer through the first secure socket connection and transmit the page through the second secure socket connection to the local computer. 
   
   
       54 . The system according to  claim 53 , wherein the processor is configured to generate an indication on the display that the field is to be filled in by the user by means of the input transducer of the information protection device. 
   
   
       55 . The system according to  claim 44 , wherein the information protection device comprises an output transducer, which is configured to prompt the user to input the data. 
   
   
       56 . The system according to  claim 55 , wherein the remote computer is configured to convey a certificate over the network to the local computer, and wherein the information protection device is configured to verify that the certificate is valid and to output via the output transducer an indication that the certificate is valid. 
   
   
       57 . An information protection device, for authenticating a user of a local computer on a remote computer, the device comprising:
 a communication interface for communicating with a local interface of the local computer;   an input transducer, which is coupled to receive an access code that is input by the user;   a memory, which is configured to hold an encryption key; and   an encryption processor, which is configured to encrypt the access code using the encryption key and to convey the encrypted access code via the local interface to the local computer, so as to cause the encrypted access code to be conveyed via the local computer over a network to the remote computer, for authentication of the user by decryption of the encrypted access code.   
   
   
       58 . The device according to  claim 57 , wherein the encryption processor is coupled to receive the encryption key from the local computer via the communication interface after transmission of the encryption key by the remote computer over the network to the local computer. 
   
   
       59 . An information protection device for use by a user of a local computer, which is in communication with a remote computer via a physical communication link over a network the device comprising:
 a communication interface for communicating with a local interface of the local computer;   an input transducer, which is coupled to receive data that are input by the user; and   a processor, which is configured to set up a secure tunnel to the remote computer over the physical communication link via the local computer, and to encrypt the received data for transmission via the secure tunnel to the remote computer such that the encrypted data transmitted through the secure tunnel can be decrypted only using a key held by the remote computer that is unavailable to the local computer.   
   
   
       60 . An information protection device, for authenticating a user of a local computer on a remote computer, the device comprising:
 a communication interface for communicating with a local interface of the local computer;   an input connector, which is configured to receive an output connector of an input transducer, which is operable by the user to input an access code;   a memory, which is configured to hold an encryption key; and   an encryption processor, which is configured to encrypt the access code using the encryption key and to convey the encrypted access code via the local interface to the local computer, so as to cause the encrypted access code to be conveyed via the local computer over the network to the remote computer, for authentication of the user by decryption of the encrypted access code.   
   
   
       61 . An information protection device, for authenticating a user of a local computer on a remote computer, the device comprising:
 a communication interface for communicating with a local interface of the local computer;   an input connector, which is configured to receive an output connector of an input transducer, which is operable by the user to input data; and   a processor, which is configured to set up a secure tunnel to the remote computer over a physical communication link via the local computer, and to encrypt the received data for transmission via the secure tunnel to the remote computer such that the encrypted data transmitted through the secure tunnel can be decrypted only using a key held by the remote computer that is unavailable to the local computer.

Join the waitlist — get patent alerts

Track US2010180120A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.